Skip to content

AI governance

Your company’s AI, audited machine by machine.

A read-only agent maps the AI and security posture of each machine — the groundwork for ISO/IEC 42001, read at the source.

Sign in with your company’s Google account. Microsoft coming soon.

Illustration of the dashboard: six machines, the AI found on each and the state of each check; highlighted, a local model and the two ISO/IEC 42001 numbers. Illustrative screen. Fictional data.The two numbers: coming soon.
Native standard
ISO/IEC 42001
Input for
LGPD art. 37GDPR art. 30
Agent
macOSWindows
Built in Brazil
PortugueseEnglish

What we can’t see yet is written on this page.See the limits

01Shadow AI

You’ve lived through at least one of these.

At 50 to 500 people, all of this lands on an IT team that’s already stretched.
  1. Nobody has the list

    Marketing uses one AI, legal another, IT a third. Which one runs on which machine, nobody can say.

  2. A model on a laptop

    Someone installed a model that runs on their own laptop. No agentless tool can see it.

  3. The customer questionnaire

    A customer asks how you govern AI use. The honest answer is a spreadsheet and good intentions.

  4. The proof is a screenshot

    The auditor wants evidence the control worked in March. All you have is today’s screenshot.

02Why now

AI moved in. Governance didn’t.

In Brazil, the data protection authority (ANPD) has set aside 20 enforcement actions on AI and emerging technologies for 2027.

Source: ANPD, Resolution CD/ANPD No. 30/2025 (2026–2027 Priority Topics Map)

03The product

See. Measure. Fix. Prove.

Inventory

The AI on each machine

Assistants, agentic editors, local models like Ollama — plus disk encryption, firewall, antivirus and updates on each machine.

What the agent reads
An inventory of six AI tools, the type of each one, how many machines it is on and whether it is running; local models are flagged with a warning. Illustrative screen. Fictional data.

ISO/IEC 42001

Two numbers, never one grade Coming soon

Coverage: how much of the standard was assessed. Conformity: of that, how much passes. Unassessed never counts as failure.

The two ISO/IEC 42001 numbers, coverage and conformity, and the catalog’s eight controls with the status of each. Illustrative screen. Fictional data.

Actions

The fix comes attached Coming soon

Each failure becomes an action: owner, due date, fix. Accepted risk needs a reason and never counts as a pass.

One open action, with owner, due date and the fix guidance; the second action is collapsed. Illustrative screen. Fictional data.

Evidence

Proof any auditor can check Coming soon

Every result joins a signed hash chain that any auditor can verify without taking our word for it.

Provenance
Three chained records, each with the previous hash and its own, and an intact verification. Illustrative screen. Fictional data.

04Provenance

A polished report proves nothing.

April 2026

A US compliance startup valued at $300 million was removed from the Y Combinator directory after allegations that its reports were written before the evidence existed — the same passage in 493 of 494. The company denies it.

Sources: TechCrunch, 4 Apr 2026 · The Tech (MIT), 9 Apr 2026 · DeepDelver, 19 Mar 2026

Since then, the buying question has changed: where did each piece of evidence come from?

  1. Read on the machine Live

    Every submission leaves the machine signed with the device’s own key. The data comes from it, not from us.

  2. Chained and signed Coming soon

    Each result carries the previous one’s hash and our signature. Alter one record and every later one breaks.

  3. Checked from outside Coming soon

    Any auditor recomputes the chain with the public key, no login needed. The answer is “intact” or the exact break.

Verify a dossier

Preview · coming soon

Intact — the chain closes end to end

A preview of verifying a dossier, with the chain of the latest records and a demonstration of an edit that verification points out. Illustrative screen. Fictional data.

Verification can say no. That’s what makes the yes worth something.

The chain, the signature and public verification are not live yet. Until they are, nothing here is called signed proof.

05How it works

One machine first. Then the fleet.

Illustrative screen. Fictional data.

  1. The sign-in screen, with the button to continue with Google.

    Create an account

    Sign in with your company’s Google account, create the organization and invite your team with roles.

  2. The terminal with the install command and the agent’s reply; on screen, the machine already reporting.

    Install the agent

    The screen generates one command with the key. Run it on the machine as an administrator: it enrolls right away.

  3. The machine right after its first reading, with the AI found and the finding.

    See what it finds

    The machine shows up the moment the agent installs — AI, encryption, antivirus, updates. Then a fresh read every six hours.

  4. The action going from open to done after the next reading.

    Fix and follow up Coming soon

    Each failure becomes an action with a deadline. The next reading confirms the fix. Signed proof is coming soon.

    Create account

06Transparency

The agent reads. Only you change things.

It blocks, changes and fixes nothing on your machines. On principle: whoever performs a control can’t attest to it.

What the agent reads — and what it never reads

The same words as the Devices screen, inside the product.

Reads

  • Machine name, serial number and whether the company manages it
  • Operating system version and build
  • Disk encryption, firewall, antivirus, screen lock, Secure Boot and the system update settings
  • Installed software, with versions
  • AI tools installed and whether they are running

Never reads

  • File, e-mail or message content
  • Anything on the screen
  • The clipboard
  • The addresses of sites visited
  • Keystrokes
  • AI tool prompts or conversations
  • Each machine’s raw report: deleted after 90 days. Evidence is the verified result, not the raw data.
  • Your environment data is yours. We process it on your company’s behalf, only to deliver the service.
  • Account name: collected to tie a device to a person. Your company can switch it off on screen.

07Declared limits

Better said now than at the audit.

Proof is our business. So here, in writing, is what we can’t see yet:
  1. 01

    Personal, unmanaged devices

    AI used on a device the company doesn’t manage is out of our reach. There, only internal policy covers it.

  2. 02

    AI in the browser

    The agent sees programs, not websites. AI used in the browser — personal accounts included — doesn’t show up yet.

  3. 03

    Cloud and Linux, not yet

    No Google Workspace, Microsoft 365 or AWS connectors yet. The agent runs on macOS and Windows.

  4. 04

    We don’t issue the certificate

    Accredited certification bodies certify ISO/IEC 42001. We deliver the readings and, soon, the proof.

What no source verifies counts as not assessed: it lowers coverage, never conformity.

08MSP partners

We audit. The work stays yours.

Fixing what fails — and billing for it — stays your work. We never touch the environment.

Roadmap, not yet available

  • A signed installer for your RMMComing soon
  • One console for all your clientsOn the roadmap
  • Your brand on your clients’ screensOn the roadmap

09Questions

What people ask before installing.

Does the agent read my files, e-mail or prompts?

No. It reads the machine: name, serial number, operating system, disk encryption, firewall, antivirus, screen lock, Secure Boot, updates, installed software and which AI tools are present and running. Never file, e-mail or message content, the screen, the clipboard, sites visited or keystrokes — nor AI prompts or conversations. Full list above, same as in the product.

Does the agent change anything on the machine?

No. It blocks nothing, changes no settings and installs nothing but itself. It reads every six hours and signs each submission with the device’s own key. It doesn’t replace your antivirus or EDR — we’re not competing for that slot. Revoke a device on screen and it stops reporting right away.

What does Atesto cover today?

Today: readings from macOS and Windows machines running the agent — AI installed and running, and security posture. ISO/IEC 42001 assessment, with guided questions on policy, roles, impact, suppliers, incidents and communication, is coming soon. Linux and cloud connectors aren’t there yet; Microsoft 365 is next.

Do you issue the ISO/IEC 42001 certificate?

No — and no software vendor can. Accredited certification bodies certify. Atesto’s job is different: read the machines all year and, soon, deliver proof your auditor verifies independently instead of requesting it by e-mail.

Why two numbers instead of one score?

Because one score blends “we checked and it’s wrong” with “nobody has looked yet”, and each calls for the opposite action. Coverage says how much was assessed; conformity, how much of that passes. One failing machine fails the check — “almost all” isn’t an answer. A failed reading never becomes a failure. And you can redo the math by hand.

What arrives with signed proof?

The evidence engine. Each result starts carrying the previous one’s hash and our signature; what we store goes into storage that refuses edits and deletions until retention ends, including by us; and public verification goes live. Until then, nothing in this product is called signed proof.

How much does it cost?

Pricing isn’t final yet. When it is, it goes on this page for anyone to see — no “contact sales” required. That part is already decided.

Can I roll it out to the whole fleet?

Today, one machine at a time: the same key works for the whole fleet, and each machine gets its own identity, which survives renames and reinstalls and can be revoked on screen without touching the others. The signed installer for GPO or RMM rollout is coming soon.

Start with one machine.

Create an account, install the agent and see what it finds. What we can’t see yet is written above.